The US government warns that Russia state hackers are coming after your router

| Source: Ars Technica AI

Tags: CISA, Russian FSB, Ghost Blizzard, Berserk Bear, SNMP, router security, botnet, critical infrastructure

CISA and five allied governments (Australia, Denmark, New Zealand, UK) issued a joint advisory warning that Russian FSB Center 16 — tracked as Ghost Blizzard and Berserk Bear — is mass-compromising SOHO routers via default SNMP credentials to build residential proxy botnets for attacks on energy, defense, and financial infrastructure.

Details

CISA, alongside governments from Australia, Denmark, New Zealand, and the UK, issued a joint advisory Monday attributing ongoing mass-compromise of home and small-office routers to Russian FSB Center 16 — a group tracked under multiple names including Berserk Bear, Energetic Bear, Ghost Blizzard, and Static Tundra. The actors are building residential proxy botnets to obscure attacks against critical infrastructure sectors. The attack vector is straightforward: hackers scan IP ranges for routers with SNMP agents accepting default or common credentials. SNMP access gives them enough control to install malware and conscript devices as exit nodes. Traffic routed through residential IPs is far less likely to be flagged by enterprise firewalls and intrusion detection systems. Targeted sectors include communications, defense, energy, financial services, and government. The advisory is notable for being a rare multi-nation attribution statement — though it conspicuously omits China, which runs parallel router-compromise campaigns documented separately. CISA framed the problem honestly: previous botnet disruptions, including covert US government disinfection actions and industry takedowns by Google and others, have been whack-a-mole exercises. The agency's primary remediation advice centers on disabling SNMP where not needed, or ensuring only SNMPv3 with strong credentials is deployed.